Wireshark-users: Re: [Wireshark-users] Tool to compare dumps from two hosts and highlight inconsi
From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Fri, 19 Mar 2010 15:21:48 -0400
Kamens, Jonathan wrote:
Greetings,

I'm trying to find a tool to do something that seems to obvious that someone /must/ have written it already, but my Web searches have come up blank.

In a nutshell, I want to capture TCP packets on two hosts and then run the two packet captures through a tool which analyzes both sides of the connection and highlights anomalies. The one I'm most interested in is packets that were sent by one side and never received by the other.

Does anything like this exist?

I think pcapdiff is supposed to do that:

http://www.eff.org/testyourisp/pcapdiff/